Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34398

Опубликовано: 17 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in FreeCAD, a 3D parametric modeler. The BIM Project Manager's Load Template function does not properly validate certain properties within a project template. This vulnerability allows a remote attacker to embed malicious Python code into a specially crafted BIM project template. When a user opens this malicious template, the embedded code can be executed, potentially leading to arbitrary code execution on the user's system.

Отчет

This is an Important flaw in FreeCAD where loading a specially crafted BIM project template can lead to arbitrary code execution. The vulnerability requires user interaction to open a malicious file, but successful exploitation grants an attacker full control over the user's system, justifying its Important severity.

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2517633FreeCAD: FreeCAD: Arbitrary Code Execution via malicious BIM project template

EPSS

Процентиль: 5%
0.00153
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
1 день назад

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.

CVSS3: 7.8
debian
1 день назад

FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...

EPSS

Процентиль: 5%
0.00153
Низкий

7.8 High

CVSS3